Security researcher Olivier Laflamme has disclosed two critical root remote code execution (RCE) vulnerabilities, CVE-2026-76639 and CVE-2026-76640, affecting the Unitree G1 EDU humanoid robot. These flaws allow attackers to gain root access to the robot's Locomotion PC via network-adjacent or Bluetooth Low Energy (BLE) attack vectors.
CVE-2026-76639 involves a path traversal vulnerability in the chat_go service that leads to code execution through bashrunner. CVE-2026-76640 utilizes a BLE-based chain involving a buffer overflow in Wi-Fi provisioning. While Unitree has patched a cloud-based authorization gap that aided exploitation, there is currently no confirmed firmware release that fully addresses the underlying vulnerabilities.
Top comments (0)